Repository navigation
chore(deps): update go indirect dependencies - #112
deckhouse-BOaTswain wants to merge 1 commit into
Conversation
ℹ Artifact update noticeFile name: examples/basic-example-module/hooks/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: examples/common-hooks/tls-certificate/hooks/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: examples/dependency-example-module/hooks/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: examples/example-module/hooks/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: examples/settings-check/hooks/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: examples/single-file-app-example/hooks/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: examples/single-file-example/hooks/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
5597e2e to
0a9ebc9
Compare
966b08c to
e101419
Compare
6fe7c8f to
22269a7
Compare
78d3cf1 to
0d8bc32
Compare
ea94f1e to
244d828
Compare
1b8e0e4 to
7034be1
Compare
7034be1 to
a54e3f7
Compare
This PR contains the following updates:
v1.6.5->v1.7.1v0.18.2->v0.19.0v0.2.0->v0.2.1v29.4.0+incompatible->v29.8.2+incompatiblev0.9.3->v0.9.9v5.9.0+incompatible->v5.9.11+incompatiblev1.9.0->v1.10.1v2.9.2->v2.9.6v1.4.3->v1.4.4v0.23.1->v0.24.0v0.25.5->v0.29.2v0.25.5->v0.29.2v0.25.5->v0.29.2v0.25.5->v0.29.2v0.26.0->v0.29.2v0.25.5->v0.29.2v0.25.5->v0.29.2v0.25.5->v0.29.2v0.25.5->v0.29.2v0.25.5->v0.29.2v0.25.5->v0.29.2v0.25.5->v0.29.2v1.3.2->v1.3.3v0.21.3->v0.22.1v1.0.0->v1.1.0v0.12.17->v0.12.19v0.1.6->v0.1.9v1.3.5->v1.4.0v0.7.7->v0.9.2v1.9.3->v1.9.5v1.23.2->v1.25.0v0.6.2->v0.6.3v0.66.1->v0.72.0v0.16.1->v0.22.0v1.9.4->v1.10.2v0.19.0->v0.20.2v1.19.0->v1.20.0v1.1.1->v1.2.0v1.2.0->v1.2.2v0.12.2->v0.12.3v0.30.0->v0.50.3v3.5.0->v3.7.2v3.0.4->v3.0.5v0.58.0->v0.60.0v0.36.0->v0.37.0v0.22.0->v0.23.0v0.47.0->v0.48.0v0.45.0->v0.46.0v0.41.0->v0.42.0v0.11.0->v0.16.0v2.4.0->v2.5.0v3.4.0->v3.5.2v3.5.1->v3.5.2v0.35.8->v0.37.1v0.35.8->v0.37.1v0.35.8->v0.37.1v0.35.8->v0.37.1v0.23.3->v0.25.2v6.3.2->v6.4.2Release Notes
cloudflare/cfssl (github.com/cloudflare/cfssl)
v1.7.1Compare Source
Changelog
ab47f0dMerge pull request #1450 from upodroid/k8s-archesf26318ebuild releases for riscv64 and ppc64lev1.7.0Compare Source
Changelog
5c9bfdfAdd scripts to regenerate {api,bundler,ubiquity}'s testdata2adc622Create semgrep.ymlfaaff55Fixes #1237 partially by updating test data certificates to be validdd8f9efGithub actions linter uses golangci-lint@v1.57adad8d8Merge pull request #1 from ang-cloudflare/fix-pr-1434-review-findings12a0addMerge pull request #1055 from akoserwal/master361a3a5Merge pull request #1364 from cloudflare/dependabot/go_modules/golang.org/x/crypto-0.21.003f2681Merge pull request #1365 from cloudflare/dependabot/go_modules/github.com/go-sql-driver/mysql-1.8.0d6d030aMerge pull request #1368 from cloudflare/dependabot/go_modules/github.com/google/certificate-transparency-go-1.1.891b63b5Merge pull request #1395 from cloudflare/hrushikeshdeshpande-creating-semgrep-ymlcb0a0a3Merge pull request #1408 from mitch292/mitch292/certificate-transparency-go-bump730ee58Merge pull request #1409 from mitch292/mitch292/revert-ct-go-upgrade1c1bc0bMerge pull request #1410 from mitch292/mitch292/1237-fix-test-cases6d2d0b2Merge pull request #1412 from mitch292/mitch292/fix-lintingb898d2fMerge pull request #1415 from mitch292/mitch292/go-versioned8df49Merge pull request #1416 from cloudflare/mschwarzl/dockerignore82408a1Merge pull request #1434 from elukey/mastere429e72Merge pull request #1436 from mitch292/fix-copy-extensions-security-bypass7d5fdbbMerge pull request #1445 from ang-cloudflare/ang/SECENG-13957e71a023Merge pull request #1447 from cloudflare/dianatran/goreleaser-v2800f0c5Migrate goreleaser config to v2 and limit build parallelism62db351Regenerate api's testdata214a154Regenerate bundler's testdataf8821d5Regenerate ubiquity's testdata14f61beRevert "Upgrade certificate-transparency-go from v1.1.8 to v1.3.1"05f2d4fSECENG-13957: feat: add ML-DSA-44/65/87 post-quantum key support038e4d2Update README2bc4eb0Update READMe2312d45Update certstore_development and sqlit_test dbs after testdata updatea40f86cUpdate repository to reflect required min go version of 1.20d3645c1Update semgrep.yml1a73d78Upgrade certificate-transparency-go from v1.1.8 to v1.3.1b4650b5build(deps): bump github.com/go-sql-driver/mysql from 1.7.1 to 1.8.0a421aeebuild(deps): bump github.com/google/certificate-transparency-god13ac5dbuild(deps): bump golang.org/x/crypto from 0.19.0 to 0.21.0ea2095dfix: preserve regenerated fixture coverage8994bddfix: prevent CSR extensions from overriding CA-managed key usage in copy_extensionscd8a4deignore .git to .dockerignorecontainerd/stargz-snapshotter (github.com/containerd/stargz-snapshotter/estargz)
v0.19.0Compare Source
Security Updates
kubelet configurationsection in docs/overview.md for details.Notable Changes
docker/cli (github.com/docker/cli)
v29.8.2+incompatibleCompare Source
v29.8.1+incompatibleCompare Source
v29.8.0+incompatibleCompare Source
v29.7.2+incompatibleCompare Source
v29.7.1+incompatibleCompare Source
v29.7.0+incompatibleCompare Source
v29.6.2+incompatibleCompare Source
v29.6.1+incompatibleCompare Source
v29.6.0+incompatibleCompare Source
v29.5.3+incompatibleCompare Source
v29.5.2+incompatibleCompare Source
v29.5.1+incompatibleCompare Source
v29.5.0+incompatibleCompare Source
v29.4.3+incompatibleCompare Source
v29.4.2+incompatibleCompare Source
v29.4.1+incompatibleCompare Source
docker/docker-credential-helpers (github.com/docker/docker-credential-helpers)
v0.9.9Compare Source
What's Changed
Full Changelog: docker/docker-credential-helpers@v0.9.8...v0.9.9
v0.9.8Compare Source
What's Changed
Full Changelog: docker/docker-credential-helpers@v0.9.7...v0.9.8
v0.9.7Compare Source
What's Changed
Full Changelog: docker/docker-credential-helpers@v0.9.6...v0.9.7
v0.9.6Compare Source
What's Changed
Full Changelog: docker/docker-credential-helpers@v0.9.5...v0.9.6
v0.9.5Compare Source
What's Changed
Full Changelog: docker/docker-credential-helpers@v0.9.4...v0.9.5
v0.9.4Compare Source
What's Changed
Full Changelog: docker/docker-credential-helpers@v0.9.3...v0.9.4
evanphx/json-patch (github.com/evanphx/json-patch)
v5.9.11+incompatibleCompare Source
v5.9.10+incompatibleCompare Source
fsnotify/fsnotify (github.com/fsnotify/fsnotify)
v1.10.1Compare Source
Changes and fixes
inotify: don't remove sibling watches sharing a path prefix (#754)
inotify, windows: don't rename sibling watches sharing a path prefix
(#755)
v1.10.0Compare Source
This version of fsnotify needs Go 1.23.
Changes and fixes
inotify: improve initialization error message (#731)
inotify: send Rename event if recursive watch is renamed (#696)
inotify: avoid copying event buffers when reading names (#741)
kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a bad entry no longer aborts Watcher.Add for the whole directory (#748)
kqueue: drop watches directly in Close() to fix a file descriptor leak when recycling watchers (#740)
windows: fix nil pointer dereference in remWatch (#736)
windows: lock watch field updates against concurrent WatchList to fix a race introduced in v1.9.0 (#709, #749)
fxamacker/cbor (github.com/fxamacker/cbor/v2)
v2.9.6Compare Source
v2.9.6 fixes 12 bugs, including an important fix for apps that decode CBOR maps into Go maps, and has one behavior change. API is unchanged but more errors are detected.
Most of these bugs were identified while improving tests and reviewing code for an upcoming release.
Tests and fuzz tests were extended.
Upgrading to v2.9.6 from all prior versions is recommended.
🐞 Important Fix
Not affected:
map[any]any, and intoany(with unchangedDefaultMapType).For use cases outside the "not affected" list, decoding a CBOR null or undefined map key or value (including
55799(null)) into a Go map whose key or value type is of bool, integer, float, or string kind kept the previous map entry's key or value (instead of the zero value). See PR #855 for details.Decoding CBOR null or undefined into an interface that holds a value now sets it to nil, matching encoding/json (v1 and v2). Previously, the interface kept its value (PR #827), which was not the intended behavior.
What's Changed
Some of these bugs could only be triggered by incorrect usage in user apps, such as invalid struct tags or an unsupported DefaultByteStringType setting, etc. None of these bugs were reported by a project affected by them.
Decoding
Encoding
CI / GitHub Actions and Docs
Full Changelog: fxamacker/cbor@v2.9.4...v2.9.6
v2.9.5Compare Source
This version was tagged from the wrong branch by mistake and is retracted.
Use v2.9.6 (https://github.com/fxamacker/cbor/releases/tag/v2.9.6) instead.
v2.9.4Compare Source
This release fixes potential panics when decoding a CBOR map whose key decodes to an uncomparable Go value under certain conditions.
Not affected: user apps that don't register tag types and don't use map key types that are either named empty interfaces (e.g.
type MyAny any) or contain interfaces.These potential panics can be encountered when one of these two conditions is met:
TagSetinterface) that is an array or struct with uncomparable orinterface{}element or field type, orThis was identified while improving tests and reviewing code for an upcoming release.
Tests and fuzz tests were extended to cover this bug.
Upgrading to v2.9.4 is recommended.
What's Changed
Full Changelog: fxamacker/cbor@v2.9.3...v2.9.4
v2.9.3Compare Source
This release fixes a potential panic when decoding into a
time.Timefrom a CBOR byte string, map, or array under certain conditions.Not affected: standard CBOR time data (RFC 8949 tag 0 or tag 1), and decoders configured with
timeTag = DecTagRequired.Upgrading to v2.9.3 is recommended.
The panic stack trace was publicly reported on 2026-08-17, and the fix was released the same day. Fuzz testing was extended to cover this class of bug, and fuzzing of v2.9.3 is ongoing.
What's Changed
Configuration
📅 Schedule: Branch creation - "before 06:00 on monday" in timezone UTC, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Renovate Bot.